VulnerabilityModified
CVE-2016-0238
This could allow an attacker to obtain sensitive information using man in the middle techniques.
LOW 3.7EPSS 0.94%
Does this matter?
Lower severity and a low EPSS score (0.94%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409
- CVSS 3.0
- 3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.94% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/security guardium
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg21989124Vendor Advisory
- http://www.securityfocus.com/bid/99379Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/110409Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21989124Vendor Advisory
- http://www.securityfocus.com/bid/99379Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/110409Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.